NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #467 most downloaded on Packagist
Adds CORS (Cross-Origin Resource Sharing) headers support in your Symfony application
Last release 8 months ago
12 Jan 2026
Ships fairly regularly
a new release about every 8 months
Nearly every release is documented
notes for 28 of 28 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
28 releases · first in 2013
Removed xml configuration by @maxhelias in #206
Full Changelog: 2.6.0...2.6.1
Remove default value for allow private network path config by @maciejziemichod in #202
Full Changelog: 2.5.0...2.6.0
One column per quarter.
Fixed deprecation notice in Symfony 7.1 #200
Full Changelog: 2.4.0...2.5.0
What's Changed Added Symfony 7 support ( #193 ) Dropped Symfony 4 support ( #193 ) Added bundle config ( #184 ) Full Changelog : 2.3.1...2.4.0
Full Changelog: 2.3.1...2.4.0
Allow psr/log ^2 || ^3 by @michalbundyra in #182
Full Changelog: 2.3.0...2.3.1
Downgraded CacheableResponseVaryListener 's priority from 0 to -10 to ensure it runs after FrameworkExtraBundle listeners have set their cache headers
CacheableResponseVaryListener's priority from 0 to -10 to ensure it runs after FrameworkExtraBundle listeners have set their cache headers (#179)expose_headers to a wildcard '*' which exposes all headers, this works as long as allow_credentials is not enabled as per the spec (#132)skip_same_as_origin flag (default to true which is the old behavior) to allow opting out of skipping the CORS headers in the response if the Origin matches the application's hostname (#178)Added support for Symfony 6
Fixed response for unauthorized headers containing a reflected XSS
Added Vary: Origin header to cacheable responses to make sure proxies cache them correctly
Reverted CorsListener priority change as it was interfering with normal operations. The priority is back at 250.
BC Break: Downgraded CorsListener priority from 250 to 28, this should not affect anyone but could be a source in case of strange bugs
Access-Control-Allow-Origin: null headers to mark blocked requestsFixed preflight request handler hijacking regular non-CORS OPTIONS requests.
Fixed preflight responses to always include Origin in the Vary HTTP header
Origin in the Vary HTTP header* Compatibility with Symfony 4
* Fixed regression in 1.5.2
Fixed bundle initialization in case paths is empty
Fixed forced_allow_origin_value to always set the header regardless of CORS, so that requests can properly be cached even if they are not always acces
forced_allow_origin_value to always set the header regardless of CORS, so that requests can properly be cached even if they are not always accessed via CORSAdded an forced_allow_origin_value option to force the value that is returned, in case you cache responses and can not have the allowed origin automat
forced_allow_origin_value option to force the value that is returned, in case you cache responses and can not have the allowed origin automatically set to the Origin header
Access-Control-Allow-Headers being sent even when it was emptyFixed requirements to allow Symfony3
Added an origin_regex option to allow defining origins based on regular expressions
origin_regex option to allow defining origins based on regular expressionsFixed a security regression in 1.3.2 that allowed GET requests to be executed from any domain
Removed 403 responses on non-OPTIONS requests that have an invalid origin header
Fixed path key normalization to allow dashes in paths
Added support for host-based configuration of the bundle
Bumped symfony dependency to 2.1.0+
allow_methods was not configured for a given pathFixed issue when allow_origin is set to * and allow_credentials to true.
allow_origin is set to * and allow_credentials to true.Added ability to set a wildcard on accept_headers
* Initial release
Your coding agent can read these notes before it upgrades. Set up the MCP server →